Skip to main content

CVE-2006-4246

Severity Low
Score 3.6/10

Summary

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

  • LOW
  • LOCAL
  • NONE
  • NONE
  • PARTIAL
  • PARTIAL

References

Advisory Timeline

  • Published